diff options
author | Mateja <mail@matejamaric.com> | 2020-10-03 00:10:38 +0200 |
---|---|---|
committer | Mateja <mail@matejamaric.com> | 2020-10-03 00:10:38 +0200 |
commit | 1e44886d6f53d5bb9621211810fdea247f7fbd71 (patch) | |
tree | 07067f1313123908121bac92c8cd0a86f5e98f43 /admin.php | |
parent | e01eaf5fe114f47f58ddcd81242af786ee06d425 (diff) | |
download | old-php-yota-1e44886d6f53d5bb9621211810fdea247f7fbd71.tar.gz old-php-yota-1e44886d6f53d5bb9621211810fdea247f7fbd71.zip |
moved notes
Diffstat (limited to 'admin.php')
-rw-r--r-- | admin.php | 55 |
1 files changed, 23 insertions, 32 deletions
@@ -1,41 +1,32 @@ <?php session_start(); -# DB CONNECT -try { - $user = "yota_user"; - $password = "leex3EThieK0ieLaiVaicaifef5eecei"; - $database = "yota_call_db"; - $conn = new PDO("mysql:host=localhost;dbname=$database", $user, $password); - $conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); -} catch (PDOException $e) { - echo "<p>Error!: " . $e->getMessage() . "</p>"; - die(); -} - -# SHOLUD SOMETHING BE APPROVED? -if ($_SERVER["REQUEST_METHOD"] == "POST" && isset($_POST['id']) ) { - $stmt = $conn->prepare("UPDATE activities SET approved = true WHERE id=:id"); -echo "lol:" . $_POST['id']; - $stmt->bindParam(':id', $_POST['id']); - $stmt->execute(); -} - # IS LOGIN LEGITIMATE? if ($_SERVER["REQUEST_METHOD"] == "POST" && isset($_POST['email']) && isset($_POST['password'])) { - try { - $stmt = $conn->prepare("SELECT * FROM admins WHERE email=:email"); - $stmt->bindParam(':email', $_POST['email']); - $stmt->execute(); - $row = $stmt->fetch(); - if (password_verify($_POST['password'], $row['password'])){ - $_SESSION['admin'] = true; - } else { - $_SESSION['admin'] = false; + # DB CONNECT + try { + $user = "yota_user"; + $password = "gahdeer6shai9hogai2sai4quuaj1eVu"; + $database = "yota_call_db"; + + $conn = new PDO("mysql:host=localhost;dbname=$database", $user, $password); + $conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); + + $stmt = $conn->prepare("SELECT * FROM admins WHERE email=:email"); + $stmt->bindParam(':email', $_POST['email']); + $stmt->execute(); + $row = $stmt->fetch(); + + if (password_verify($_POST['password'], $row['password'])){ + $_SESSION['admin'] = true; + } else { + $_SESSION['admin'] = false; + } + } catch (PDOException $e) { + echo "<p>Error!: " . $e->getMessage() . "</p>"; } - } catch (PDOException $e) { - echo "<p>Error!: " . $e->getMessage() . "</p>"; - } + $stmt=null; + $conn=null; } ?> <!DOCTYPE html> |